CVE-2012-1889: Microsoft XML Core Services Memory Corruption Vulnerability
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Other sources
Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1889?
CVE-2012-1889 is classified as critical due to its potential to allow remote code execution.
How do I fix CVE-2012-1889?
You can fix CVE-2012-1889 by applying the security updates provided by Microsoft for affected versions of XML Core Services.
Which versions are affected by CVE-2012-1889?
CVE-2012-1889 affects Microsoft XML Core Services versions 3.0, 4.0, 5.0, and 6.0.
Can CVE-2012-1889 cause a denial of service?
Yes, CVE-2012-1889 can lead to denial of service due to memory corruption that may crash the application.
What types of attacks can exploit CVE-2012-1889?
CVE-2012-1889 can be exploited through crafted web pages that trigger the vulnerability when accessed.